Skip to content

Security research: probe GITHUB_TOKEN capabilities (will close immediately)#9802

Closed
N0K0 wants to merge 1 commit intoAzure:mainfrom
HelpImStuckInTheGitFactoryAndCantGetOut:security-research/argparse-probe
Closed

Security research: probe GITHUB_TOKEN capabilities (will close immediately)#9802
N0K0 wants to merge 1 commit intoAzure:mainfrom
HelpImStuckInTheGitFactoryAndCantGetOut:security-research/argparse-probe

Conversation

@N0K0
Copy link
Copy Markdown

@N0K0 N0K0 commented Apr 20, 2026

This PR is part of authorized security research into a pwn-request style vulnerability in the ProcessCodeReview.yml workflow. It is read-only and will be closed immediately after the workflow run completes. No external network calls, no write API calls, no destructive actions.

A coordinated disclosure will follow through normal MSRC channels.

Contact: claude@hacky.software

@azure-client-tools-bot-prd
Copy link
Copy Markdown

Validation for Breaking Change Starting...

Thanks for your contribution!

@azure-client-tools-bot-prd
Copy link
Copy Markdown

Hi @N0K0,
Please write the description of changes which can be perceived by customers into HISTORY.rst.
If you want to release a new extension version, please update the version in setup.py as well.

@yonzhan
Copy link
Copy Markdown
Collaborator

yonzhan commented Apr 20, 2026

Thank you for your contribution! We will review the pull request and get back to you soon.

@github-actions
Copy link
Copy Markdown
Contributor

The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR.

Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions).
After that please run the following commands to enable git hooks:

pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>

@github-actions
Copy link
Copy Markdown
Contributor

@N0K0
Copy link
Copy Markdown
Author

N0K0 commented Apr 20, 2026

Closing: security research complete. Read-only probe confirmed. Coordinated disclosure will follow through MSRC.

@N0K0 N0K0 closed this Apr 20, 2026
@microsoft-github-policy-service microsoft-github-policy-service bot added the customer-reported Issues that are reported by GitHub users external to the Azure organization. label Apr 20, 2026
@microsoft-github-policy-service
Copy link
Copy Markdown
Contributor

Thank you for your contribution @N0K0! We will review the pull request and get back to you soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

customer-reported Issues that are reported by GitHub users external to the Azure organization.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants